Pradosh Das

Operations Associate

Cuttack, Odisha, India20 yrs 11 mos experience

Key Highlights

  • Over 15 years in IT and data security.
  • Expert in enterprise risk management and privacy compliance.
  • Led comprehensive risk management frameworks for sensitive data.
Stackforce AI infers this person is a Privacy Compliance and Risk Management expert in the Fintech sector.

Contact

Skills

Core Skills

Enterprise Risk ManagementPrivacy ComplianceCybersecurityData PrivacyRisk Management

Other Skills

Microft purviewThird-Party Vendor ManagementOne trustPDPAThird Party Risk Management (TPRM)DPDP ACTPDPLRisk Management ToolsSecurity Incident & Event ManagementComputer ForensicsInformation TechnologyIT LawRequirements AnalysisSoftware as a Service (SaaS)A++

About

With over 15 years of experience in IT and data security, I specialize in enterprise risk management and privacy compliance. At Infosys BPM, I lead the strategic design and implementation of a comprehensive risk management framework to safeguard Provident Fund and Pension data. This includes developing robust risk identification, assessment, and mitigation strategies to ensure compliance with global data protection standards such as GDPR and CCPA. Leveraging expertise in Privacy Impact Assessments, ROPA, and consent management using tools like OneTrust, I enable secure and compliant data practices. My mission is to drive proactive risk mitigation strategies and foster organizational resilience, helping teams navigate complex regulatory landscapes with confidence.

Experience

20 yrs 11 mos
Total Experience
4 yrs 5 mos
Average Tenure
--
Current Experience

Infosys bpm

2 roles

Senior Manager Risk and Compliance

Oct 2024Feb 2025 · 4 mos

  • As Senior Manager in the Risk and Privacy domain at Infosys BPM, I lead the strategic design and execution of a comprehensive enterprise risk management framework, ensuring proactive risk mitigation for Provident Fund (PF) and Pension data. My efforts have strengthened organizational resilience by tailoring robust risk identification, assessment, and mitigation strategies aligned with company objectives. A key achievement is the successful development of a comprehensive privacy program that adheres to global data protection regulations, including GDPR and CCPA, safeguarding sensitive financial data.
  • Notable achievements include:
  • ● Spearheaded the design and implementation of a robust risk management framework for PF and Pension data, ensuring full compliance with industry standards.
  • ● Led the creation of a global privacy strategy, ensuring compliance with diverse data protection laws and implementing policies that ensured ongoing protection of sensitive data.
  • ● Directed cross-functional teams to manage data breach incidents, utilizing advanced incident response protocols to enhance compliance and operational security.
  • ● Deployed advanced security measures like AI-driven anomaly detection and automated compliance tracking to reinforce data security for pension records.
  • ● Designed and led training initiatives to foster a culture of security awareness, significantly improving internal compliance adherence.
Microft purviewThird-Party Vendor ManagementOne trustPDPAThird Party Risk Management (TPRM)DPDP ACT+3

Senior Risk Manager

Oct 2024Feb 2025 · 4 mos

  • Strategized & operationalized an enterprise-wide Risk Management Framework specific to Provident Fund (PF) &Pension data, integrating dynamic risk assessments with business objectives to drive resilience &regulatory alignment. Led the design and execution of a global privacy program covering GDPR, CCPA, and pension-specific data laws, safeguarding personally identifiable and financial data across multi-jurisdictional operations. Established enterprise privacy governance, drafting robust internal policies and regulatory frameworks to future-proof operations against legal and audit scrutiny. Directed enterprise-wide incident response mechanisms, managing forensic investigation, impact assessment, regulator notification, and post-breach remediation plans. Elevated data security posture by deploying advanced encryption standards, data masking, and access governance protocols tailored for pension record confidentiality. Governed third-party privacy risk, developing DPAs and onboarding protocols while embedding contractual safeguards into external data handling engagements.

Global cybersecurity association (gca)

Member

Aug 2023Oct 2023 · 2 mos · Remote

Third-Party Vendor ManagementData PrivacyCybersecurityGeneral Data Protection Regulation (GDPR)DPDP ACTPrivacy Compliance

Tutelr.

Compliance Officer

Oct 2022Sep 2024 · 1 yr 11 mos · Remote · Remote

  • At Tutelr Infosec, I played a pivotal role in ensuring privacy compliance for cloud computing, email security, and application security projects. I conducted in-depth Privacy Impact Assessments (PIA) and Transfer Impact Assessments (TIA), advocating for data minimization and ensuring secure and GDPR-compliant data transfers. My proactive approach in maintaining up-to-date regulatory knowledge and driving risk mitigation strategies resulted in enhanced compliance across the organization.
  • Key achievements include:
  • ● Led successful Privacy Impact Assessments for key projects, mitigating privacy risks and ensuring full GDPR compliance.
  • ● Spearheaded the implementation of robust consent management systems using OneTrust tools, allowing customers to manage their preferences and ensuring GDPR-compliant documentation.
  • ● Championed data minimization practices, optimizing data retention policies to align with GDPR’s strict requirements, reducing data exposure and risk.
  • ● Delivered privacy and risk management training, equipping teams with the knowledge needed to handle sensitive data securely and in compliance with evolving regulations.
Microft purviewThird-Party Vendor ManagementPDPAThird Party Risk Management (TPRM)DPDP ACTPrivacy Compliance+2

Tutelrinfosec pvt. ltd.

Compliance Officer

Oct 2022Sep 2024 · 1 yr 11 mos

  • Led high-impact Privacy Impact Assessments (PIAs) across cloud, application, and email security environments, integrating privacy-by-design into technical architecture. Directed cross-border Transfer Impact Assessments (TIAs) under GDPR, implementing localization strategies and jurisdictional safeguards for lawful data transfers. Maintained proactive compliance readiness across GDPR, CCPA, DPDP Act, and PIPEDA through structured audits, regulatory watch, and internal controls. Reinforced technical privacy controls, ensuring encryption, access restriction, and audit logging per GDPR Article 32, in collaboration with cybersecurity teams. Orchestrated enterprise-grade consent and preference management systems via OneTrust, enabling transparent, traceable, and user-centric consent workflow. Drafted comprehensive internal policies, harmonizing privacy risk management with global regulatory expectations and corporate governance principles. Spearheaded capability-building programs, delivering privacy awareness and training initiatives tailored to functional risk exposure and data management roles.

Ieee standards association

Member

Oct 2022Oct 2023 · 1 yr · India · Remote

  • standardizing association
Third-Party Vendor ManagementPrivacy Compliance

Freelance

Privacy Executive

Oct 2020Sep 2022 · 1 yr 11 mos · Remote

  • In my freelance role, I worked closely with legal teams to ensure GDPR compliance across multiple projects, focusing on data privacy regulations and internal audit strategies. I developed and enforced consent management processes, risk mitigation strategies, and data retention policies to align with international data protection standards. My work contributed to strengthening privacy frameworks and policies for various clients in compliance with global data protection laws.
  • Key achievements include:
  • ● Played a critical role in maintaining GDPR compliance by conducting internal audits and assessments, identifying and addressing compliance gaps.
  • ● Collaborated with legal teams to implement GDPR-compliant consent processes and ensure transparent data collection practices.
  • ● Developed and enforced comprehensive data retention policies, ensuring compliance with GDPR’s data minimization principle.
  • ● Designed and implemented privacy policies, reinforcing customer trust and safeguarding sensitive information across all phases of project implementation.
  • ➤ Specialties: Data Privacy and Protection, Regulatory Compliance, Risk Management, Privacy Impact Assessment (PIA), Transfer Impact Assessment (TIA), Data Minimization, Consent Management, Data Security and Encryption, Governance and Policy Development, Incident Response and Breach Management, Cross-Functional Collaboration, Vendor and Third-Party Risk Management, Audit and Compliance Monitoring, Training and Awareness Programs, Data Retention and Disposal Policies, Cybersecurity Integration, Advanced Security Solutions Deployment, Legal and Regulatory Liaison, Crisis Preparedness and Response Planning, Performance Metrics and Risk Indicators.
Privacy PoliciesThird-Party Vendor ManagementThird Party Risk Management (TPRM)General Data Protection Regulation (GDPR)Privacy ProtectionPrivacy Regulations+1

Independent consultant – privacy executive

Under Adv. Divya Dwivedi, Supreme Court of India

Oct 2020Sep 2022 · 1 yr 11 mos

  • Consulted on GDPR interpretation and implementation, aligning legal provisions with practical compliance models across digital and regulated environments. Executed privacy readiness audits, identifying non-conformities, operational risks, and implementing audit-proof compliance protocols. Operationalized lawful basis models, ensuring data collection and processing aligned with GDPR Article 6(1), emphasizing informed and granular consent. Instituted data minimization and retention policies, embedding necessity, proportionality, and time-bound storage practices per GDPR Article 5. Collaborated with legal stakeholders to craft enterprise-ready privacy strategies that balanced operational agility with regulatory defensibility. Contributed to policy formulation and enforcement, standardizing organizational approaches to data protection, and user trust.

Vetics broadband

Senior Network Analyst

Oct 2012Jun 2020 · 7 yrs 8 mos · Bhubaneswar, Odisha, India · On-site

Ddce,utkal university

Visiting Faculty

Sep 2011Oct 2024 · 13 yrs 1 mo · Bhubaneswar, Odisha, India

  • lectures on DATA COMMUNICATION AND NETWORKING , ECOMMERECE , APPLICATION SECURITY , DESKTOP SECURITY ,NETWORK SECURITY ,INFORMATION SECURITY , DATA PRIVACY , DATA PROTECTION
Computer ForensicsInformation TechnologyIT LawRequirements AnalysisSoftware as a Service (SaaS)A+++5

Seraphic systems pvt ltd

Data Network Specialist

Jul 2008Sep 2012 · 4 yrs 2 mos · Bhubaneswar, Odisha, India · On-site

Tata infotech

Network Administrator

Feb 2004Jun 2008 · 4 yrs 4 mos · Bhubaneswar, Odisha, India · On-site

Education

Odisha State Open University

Master of Science — Cyber Security

Aug 2021Jul 2023

Utkal University

Bachelor of Laws - LLB — Law

Aug 2020Jul 2023

Sikkim state university

Bachelor of Science - BS — Computer Science

Aug 2000Aug 2003

IIHT Ltd

Garduate in network engineering — Computer Systems Networking and Telecommunications

Sep 1997Jun 2000

Council of higher secondary certificate

Intermideate of science — Physics/chemestry/maths/biology

Aug 1995Aug 1997

Board of Secondary Examination

HSS

Apr 1995Present

IIHT Ltd

Graduate in Network Engineering (Computer Networking)

Sikkim University, Gangtok

Bachelor of Computer Science

Utkal University

Bachelor's Degree

Stackforce found 100+ more professionals with Enterprise Risk Management & Privacy Compliance

Explore similar profiles based on matching skills and experience